• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

Just had a weired pop-up on start-up

GasX

Lifer
I am visiting my parents and their computer was utterly polluted with Spyware which I killed with Spybot and Adaware. However, when you reboot a pop-up still comes up saying:

Windows alert: Do you want to install Casino....

[Yes] [No]

How do I kill this?

Oh yeah, and how do I get in to edit the processes that begin on start-up?

thx...
 
ANS1: Visit spywareinfo.com forums. Better info there... get cwshredder.zip and hijackthis.zip then, to be nice:

The following assumes you are working on an XP machine and behind a hardware firewall or have a software firewall installed, if not, go into properties for network neighborhood, properties for local area connection, and advanced and enable the XP Firewall.

After running Spybot and Adaware w/ latest reference updates, then run cwshredder (available at spywareinfo). Before rebooting the last time, run msconfig and check the run items and uncheck any that are odd (you can't recognize what they do). Then reboot and run the spyware progs all again. Repeat until system is clean. Do not start a browser session during this time.

When clean, run hijack this (also available at spywareinfo.com) and see if there are any odd Browser helper objects (BHO's) still installed.

That should do it. Spybot and AdAware miss some startup tasks that may reinstall the spyware stuff, so I found I had to find them and do that manually. Since they all have weird names you need to uncheck anything that might be bad. If you disable a sound driver or something you can run msconfig again and enable it afterwards.

Lastly go to windowsupdate.microsoft.com and apply latest patches.

ANS2: MSCONFIG lets you edit startup task items.

ANS3: Tell your parents to stop clicking OK and YES willy nilly. Better yet stop surfing the web. 🙂


 
After running Spybot and Adaware w/ latest reference updates, then run cwshredder (available at spywareinfo).

check

Before rebooting the last time, run msconfig and check the run items and uncheck any that are odd (you can't recognize what they do).

check

Then reboot and run the spyware all again. Repeat until system is clean. Do not start a browser session during this time.

check

When clean, run hijack this (also available at spywareinfo.com) and see if there are any odd Browser helper objects (BHO's) still installed.

check

Pop-up still there... 🙁
 
Originally posted by: dman
ANS3: Tell your parents to stop clicking OK and YES willy nilly. Better yet stop surfing the web. 🙂

Ugh, reminds me of when I was helping a friend clean the machines on the pay-to-play LAN at his game store. A dozen different messaging programs had been installed, and hundreds of instances of spyware, as if the customers clicked "YES" to every damn pop-up that wanted to install crap on the machine. One machine had even been highjacked and was acting as a Morpheus server.
 
specifically:

"You have the Golden Palace software installed on this computer. Wanna try it for free and win $1,000,000?"

[Yes] [No]

:|
 
to get rid of that perform the following:

insert blank, formatted floppy into drive A:

goto START --> RUN --> Command and hit enter

at the DOS prompt, type A: and hit enter

at the A: prompt, type: format c: /s and hit enter

once that program finishes running, your hard drive will be like new 😀

 
Originally posted by: aircooled
regedit.

HKLM/Software/Microsoft/Windows/Current Verson/Run

See if it's there. if so delete it.
I couldn't find it, but I did find a registry key for Golden Palace which I deleted. - didn't fix the problem. I have a screen shot of "HKLM/Software/Microsoft/Windows/Current Verson/Run" but IE won't let me load my website control panel to upload it... :|
 
Back
Top